Zoom Communications, Inc.
Self-Reporting Analysis
Of all the CVEs published by Zoom Communications, Inc. as a CNA, 94.2% affect products that Zoom Communications, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Zoom Communications, Inc., 91.8% are self-published by Zoom Communications, Inc. as a CNA.
Trends Over Time
The number and severity of CVEs published by Zoom Communications, Inc. over time
Top CVEs
All CVEs published by Zoom Communications, Inc. as a CNA, regardless of affected vendor or product.
226 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-53412CRITICAL Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account | Jul 16, 2026 | 9.8 | 49 | NO | NO |
CVE-2026-22844CRITICAL A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via n | Jan 20, 2026 | 9.9 | 44 | NO | NO |
CVE-2026-53407CRITICAL Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an | Jun 12, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-53411HIGH A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to | Jul 16, 2026 | 7.8 | 37 | NO | NO |
CVE-2026-53409HIGH Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access. | Jul 16, 2026 | 7.8 | 37 | NO | NO |
CVE-2026-53410HIGH A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to | Jul 16, 2026 | 7.0 | 35 | NO | NO |
CVE-2025-64741CRITICAL Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access. | Nov 13, 2025 | 9.8 | 35 | NO | NO |
CVE-2026-30903CRITICAL External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via net | Mar 11, 2026 | 9.8 | 34 | NO | NO |
CVE-2021-34423CRITICAL A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackber | Nov 24, 2021 | 9.8 | 34 | NO | NO |
CVE-2025-49457HIGH Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | Aug 12, 2025 | 8.8 | 33 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (226 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Zoom Communications, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Zoom Communications, Inc. as a CNA — matched by CVE ID, not by organization name.